This page gathers what does not fit under Guides or Reference: licensing of the default stack, how to reach the people behind a Kumoss deployment, where release notes and the changelog will be published, and where the FAQ lives.
Licensing of the default stack
Every component that runs by default in the checked-in Compose stack is open source, with one source-available exception that is disclosed rather than hidden (the bundled but inactive Terraform binary is a second, opt-in exception). Identity has no licensing footprint at all: Kumoss speaks standard OpenID Connect and trusts any spec-faithful issuer, so a fully open-source deployment can pair it with Keycloak (Apache-2.0, CNCF Incubating) while an enterprise can point it at Entra ID, Auth0, or Okta without changing a line of code.
| Component | Role | Licence | Notes |
|---|---|---|---|
Kumoss (core, sidecars, SPA, contracts) |
The platform |
Apache-2.0 |
REUSE-compliant SPDX headers |
OpenTofu 1.12.6 |
Default IaC engine in the iac sidecar |
MPL-2.0 (Linux Foundation) |
Digest-pinned. The same image also bundles HashiCorp Terraform 1.16.0
(BUSL-1.1, not OSI), downloaded and checksum-verified at build time and
selectable via |
RustFS |
Default, bundled S3-compatible object storage for artifacts (and for Terraform state where that is enabled) |
Apache-2.0 |
Rust implementation of the S3 API; AWS S3 or Azure Blob Storage
selectable via |
PostgreSQL 17 |
core-db and phoenix-db |
PostgreSQL Licence |
— |
Redis 8 |
Fail-open cache |
Tri-licensed: AGPLv3 (OSI) / RSALv2 / SSPLv1 |
AGPLv3 option restored in Redis 8.0 |
nginx |
Reverse proxy and SPA host |
BSD-2-Clause |
— |
FastAPI, LiteLLM, React, oidc-client-ts |
Framework, model router, portal, OIDC client |
MIT |
— |
OpenTelemetry / OpenInference |
Tracing standard and semantic conventions |
Apache-2.0 |
OpenTelemetry is CNCF Graduated (2026-05-21) |
Arize Phoenix |
Trace UI and runtime prompt registry |
Elastic License 2.0 (source-available, not OSI-approved) |
The only non-OSI component; disclosed in all public material |
OpenID Connect |
Authentication protocol |
Open standard (OpenID Foundation) |
No component shipped; any compliant IdP |
Contact and support
Three channels, each with its own purpose:
-
Support request in the web application — questions about your own Kumoss deployment or about one of your sessions. It reaches the reviewers in your deployment, not the Kumoss project.
-
Issue tracker — bugs and feature requests in Kumoss itself. Check the existing issues first; Contributing covers what happens next.
-
Disclosure submission program — security vulnerabilities, reported privately and never through a public GitHub issue.
Support requests
Any signed-in user can send a support request from inside the web application. It goes to the people who hold the reviewer roles in your own Kumoss deployment — colleagues on your platform team, not the Kumoss project — through the channel your platform team connected (Slack in the reference setup), with a copy addressed to you.
From the browser, the chat-bubble Support icon in the header opens a form for up to 500 characters, plain text only — HTML and code formatting are rejected. The message carries your e-mail, the session id, the repository, branch, request, status, and a link to the session automatically, so you do not need to copy those in yourself. Contact Team (on a locked session) and Request Review (on the apply confirmation) send the same kind of message, pre-filled for that session, and flagged as a warning when the plan deletes or recreates resources. "Your question has been sent successfully" confirms delivery; "Your question could not be sent. Notifications are disabled." means your deployment has not connected a notification channel — use your organization’s usual support route and quote the session id.
The form calls POST /api/v1/notifications. The core forwards the
request to the notifications sidecar with an audience made of the
caller’s e-mail plus every user holding a panel role of editor or
higher, and the bundled sidecar posts it to Slack. When
services.notifications.enabled is false the route answers 503
Notifications are disabled.; when delivery fails it answers 502
Notification was not delivered.
Security
Report a security vulnerability through the disclosure submission program, in English — never through a public GitHub issue. The security team acknowledges a report within 48 hours, investigates its severity, and develops, tests, and publishes a fix and an advisory. See the security policy for the full process and the safe-harbor terms covering researchers who report in good faith.
Release notes
Kumoss has not published a tagged release yet. When it does, the curated highlights of each release — what is new and what it changes for the people using it — will be listed here and on the project’s GitHub Releases page.
Changelog
The unabridged, commit-level record of changes is the repository’s commit history; it is not duplicated here. Once releases exist, each GitHub Release carries the complete list of additions, changes, fixes, and deprecations since the previous one.